期刊文献+

基于软件定义网络的Crossfire攻击防御方法

Crossfire Attack Defense Method Based on Software Defined Network
下载PDF
导出
摘要 区别于常规的分布式拒绝服务攻击,利用僵尸网络发动的Crossfire攻击具有低速率不可区分的特性,这导致常规入侵检测系统难以防御此类攻击。针对该问题,设计一种检测防御Crossfire攻击的方法。该方法基于软件定义网络(SDN),首先利用网络瓶颈选择算法筛选出易受攻击的网络瓶颈节点与链路,在此基础上部署虚拟节点预防Crossfire攻击,虚拟节点应答可疑探测流,扰乱攻击者的攻击视图从而隐藏物理拓扑的网络瓶颈,并基于随机森林和双阈值自编码器检测僵尸网络,最后通过慢开始防御策略和局部快速重路由方法达到防御Crossfire攻击的目的。实验在SDN环境下进行,虚拟节点的部署能够使得瓶颈节点指标明显降低,构建的僵尸网络检测模型在精度、召回率、F1值等方面相较于传统随机森林分类模型提高近5个百分点,防御方法能够在10 s内达到缓解Crossfire攻击的效果。实验结果表明,相对其他方法,所提方法能有效检测并缓解此类攻击,且在此过程中基本不会影响到合法流量在物理拓扑中的正常转发。 Unlike conventional Distributed Denial of Service(DDoS)attacks,Crossfire attacks launched by botnets are low-speed and indistinguishable,making them difficult for traditional intrusion detection systems to defend against.To address this issue,a method for detecting and defending against Crossfire attacks is proposed,based on a Software Defined Network(SDN).The method involves several steps.First,a network bottleneck selection algorithm identifies vulnerable network bottleneck nodes and links.On this basis,virtual nodes are deployed to prevent Crossfire attacks.These virtual nodes respond to suspicious probe flows,distorted the attacker′s view,and obscured the network bottleneck in the physical topology.Botnet detection is performed using a random forest and a double-threshold autoencoder.Finally,a slow-start defense strategy and local fast rerouting method are adopted to mitigate crossfire attacks.Experiments conducted in an SDN environment show that deploying virtual nodes significantly reduces the bottleneck node index.The proposed botnet detection model performs approximately 5 percentage points better in terms of precision and recall compared to the traditional random forest classification model.The defense method effectively mitigates Crossfire attacks within 10 s.Experimental results show that the proposed method can effectively detect and mitigate such attacks in the SDN environment,with minimal impact on the normal forwarding of legitimate traffic in the physical topology.
作者 郭雷 荆山 魏亮 赵川 GUO Lei;JING Shan;WEI Liang;ZHAO Chuan(School of Information Science and Engineering,University of Jinan,Jinan 250022,Shandong,China;Jiangsu Future Networks Innovation Institute,Nanjing 211111,Jiangsu,China;Quan Cheng Laboratory,Jinan 250103,Shandong,China)
出处 《计算机工程》 CAS CSCD 北大核心 2024年第10期216-227,共12页 Computer Engineering
基金 国家自然科学基金(62172258,61702218,61672262) 山东省自然科学基金(ZR2021LZH007) 山东省重点研发计划(2021CXGC010103) 泰山学者青年专家工程项目(tsqn202211280)。
关键词 软件定义网络 Crossfire攻击 虚拟节点 僵尸网络检测 检测防御 Software Defined Network(SDN) Crossfire attack virtual node botnet detection detection and defense
  • 相关文献

参考文献5

二级参考文献84

  • 1穆祥昆,王劲松,薛羽丰,黄玮.基于活跃熵的网络异常流量检测方法[J].通信学报,2013,34(S2):51-57. 被引量:20
  • 2Zhang CK, Cui Y, Tang HY, Wu JP. State-of-the-Art survey on software-defined networking (SDN). Ruan Jian Xue Bao/Journal of Software, 2015,26(1):62-81 (in Chinese with English abstract), http://www.jos.org.cn/1000-9825/4701.htm [doi: 10.13328/j.cnki. jos.004701 ].
  • 3Open networking summit 2012.2012. bttp://opennetsummit .org/archives/apr 12/site/why.html.
  • 4McKeown N, Anderson T, Balakrishnan H, Parulkar G, Peterson L, Rexford J, Shenker S, Turner J. OpenFlow: Enabling innovation in campus networks. ACM SIGCOMM Computer Communication Review, 2008,38(2):69-74. [doi: 10.1145/1355734. 1355746].
  • 5Awduche D, Chiu A, Elwalid A, Widjaja I, Xiao XP. Overview and Principles of Internet Traffic Engineering. IETF RFC 3272, 2002.
  • 6Akyildiz IF, Lee A, Wang P, Chou W. A roadmap for traffic engineering in software defined networks. Computer Network, 2014, 71(2):1-30. [doi: 10.1016/j.comnet.2014.06.002].
  • 7Bae JJ, Suda T. Survey of traffic control schemes and protocols in arm networks. Proc. of the IEEE, 1991,79(2):170-189. [doi: 10. 1109/5.64405].
  • 8Wang N, Ho K, Pavlou G, Howarth M. An overview of routing optimization for internet traffic engineering. IEEE Communications Surveys & Tutorials, 2008,10(1):36-56. Idol: 10.1109/COMST.2008.4483669].
  • 9Awduche DO, Agogbua J. Requirements for Traffic Engineering over MPLS. RFC 2702, 1999.
  • 10Zuo QY, Chen M, Zhao GS, Xing CY, Zhang GM, Jiang PC. OpenFlow-Based SDN technologies. Ruan Jian Xue Bao/Journal of Software, 2013,24(5): 1078-1097 (in Chinese with English abstract), http://www.jos.org.cn/1000-9825/4390.htm [doi: 10.3724/SP.J. 1001.2013.04390].

共引文献89

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部